Browse CVEs

225 CVEs analyzed. 574 pending.

All Critical High Medium Low
CVE-2025-14740 6.7

Docker Desktop for Windows installer has permission assignment vulnerabilities allowing low-privileged attackers to gain code execution. Attackers can...

Feb 4, 2026
CVE-2026-1210 6.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into pages using the Happy...

Feb 3, 2026
CVE-2026-1447 5.4

The Mail Mint WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to 1.19.2, allowing unauthenticated attackers to ...

Feb 3, 2026
CVE-2026-20704 4.3

A cross-site request forgery (CSRF) vulnerability exists in ELECOM WRC-X1500GS-B and WRC-X1500GSA-B wireless routers. Attackers can trick authenticate...

Feb 3, 2026
CVE-2026-24449 4.6

This vulnerability allows attackers to calculate initial administrative passwords for affected ELECOM wireless routers using publicly available system...

Feb 3, 2026
CVE-2026-0950 5.3

The Spectra Gutenberg Blocks plugin for WordPress has an information disclosure vulnerability that allows unauthenticated attackers to read excerpts f...

Feb 3, 2026
CVE-2025-14274 5.4

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into web pages via the Bor...

Feb 3, 2026
CVE-2026-0909 5.3

The WP ULike WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Subscriber-level access o...

Feb 3, 2026
CVE-2026-25228 5.0

Signal K Server versions prior to 2.20.3 on Windows systems contain a path traversal vulnerability in the applicationData API. Authenticated users can...

Feb 2, 2026
CVE-2026-25144 5.3

A stored cross-site scripting (XSS) vulnerability exists in Talishar's in-game chat system where the playerID parameter in SubmitChat.php is saved wit...

Feb 2, 2026
CVE-2026-23476 5.4

This reflected XSS vulnerability in FacturaScripts allows attackers to inject malicious scripts into error messages that get executed in users' browse...

Feb 2, 2026
CVE-2026-24007 4.6

This CSRF vulnerability in Tuleap allows attackers to trick authenticated users into performing unauthorized actions, specifically creating artifact l...

Feb 2, 2026
CVE-2026-22780 4.4

A heap overflow vulnerability in Rizin allows attackers to execute arbitrary code or cause denial of service by tricking users into analyzing maliciou...

Feb 2, 2026
CVE-2026-1778 5.9

This vulnerability in Amazon SageMaker Python SDK disables TLS certificate verification when importing Triton Python models, allowing HTTPS connection...

Feb 2, 2026
CVE-2025-6594 4.7

This XSS vulnerability in MediaWiki's ApiSandbox.js allows attackers to inject malicious scripts into web pages viewed by other users. It affects Medi...

Feb 2, 2026
CVE-2025-6595 4.7

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's MultimediaViewer component. Attackers can inject malicious scr...

Feb 2, 2026
CVE-2025-70958 6.1

Multiple reflected cross-site scripting (XSS) vulnerabilities in Subrion CMS v4.2.1 installation module allow attackers to inject malicious JavaScript...

Feb 2, 2026
CVE-2025-70959 5.4

A stored cross-site scripting vulnerability in Tendenci CMS allows attackers to inject malicious scripts into the Jobs module. When users view affecte...

Feb 2, 2026
CVE-2025-70960 5.4

A stored cross-site scripting (XSS) vulnerability in Tendenci CMS v15.3.7 allows attackers to inject malicious scripts into forum posts that execute w...

Feb 2, 2026
CVE-2025-15395 4.3

This CVE describes an access control vulnerability in IBM Jazz Foundation that allows authenticated users to perform actions or view data beyond their...

Feb 2, 2026
CVE-2022-50980 6.5

An unauthenticated attacker on the same Controller Area Network (CAN) bus can disrupt operations by rapidly switching between configuration presets. T...

Feb 2, 2026
CVE-2022-50979 6.5

This vulnerability allows an unauthenticated attacker on the same network segment to disrupt operations by switching between multiple configuration pr...

Feb 2, 2026
CVE-2026-1760 5.3

This HTTP request smuggling vulnerability in SoupServer allows remote attackers to send specially crafted requests that bypass normal request processi...

Feb 2, 2026
CVE-2026-1757 6.2

A memory leak vulnerability in xmllint's interactive shell allows local denial-of-service attacks. When users input only whitespace, the program fails...

Feb 2, 2026
CVE-2025-6208 5.3

The SimpleDirectoryReader component in llama_index.core versions before 0.12.41 has a memory management flaw where it loads all files from a directory...

Feb 2, 2026
CVE-2025-7105 5.7

This vulnerability in LibreChat allows attackers to exploit an unrestricted fork function to create numerous content forks containing large Mermaid gr...

Feb 2, 2026
CVE-2026-20413 6.7

This CVE describes an out-of-bounds write vulnerability in the imgsys component due to missing bounds checks. It allows local privilege escalation fro...

Feb 2, 2026
CVE-2026-20414 6.7

This CVE describes a use-after-free vulnerability in the imgsys component that allows local privilege escalation. An attacker who already has System p...

Feb 2, 2026
CVE-2026-20415 5.5

This vulnerability in the imgsys component allows memory corruption due to improper locking. It enables local denial of service attacks when exploited...

Feb 2, 2026
CVE-2026-20417 5.3

This CVE describes an out-of-bounds write vulnerability in PCIe drivers that could allow local privilege escalation. Attackers with initial System pri...

Feb 2, 2026
CVE-2026-20410 6.7

This CVE describes an out-of-bounds write vulnerability in imgsys (likely MediaTek image processing subsystem) that allows local privilege escalation....

Feb 2, 2026
CVE-2026-20711 6.5

A cross-site scripting vulnerability in the email function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary user...

Feb 2, 2026
CVE-2026-22881 5.7

A cross-site scripting vulnerability in the Message function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary us...

Feb 2, 2026
CVE-2026-22888 4.9

An improper input verification vulnerability in Cybozu Garoon allows attackers to modify portal settings without proper authorization. This could bloc...

Feb 2, 2026
CVE-2026-0658 4.3

The Five Star Restaurant Reservations WordPress plugin before version 2.7.9 lacks CSRF protection on some bulk actions, allowing attackers to trick lo...

Feb 2, 2026
CVE-2026-1746 6.3

This SQL injection vulnerability in JeecgBoot 3.9.0 allows remote attackers to execute arbitrary SQL commands through the Online Report API's loadDict...

Feb 2, 2026
CVE-2026-1745 4.3

This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against the Medical Certificate Generator App 1.0, enabling u...

Feb 2, 2026
CVE-2026-1741 6.6

This CVE describes a backdoor vulnerability in the EFM ipTIME A8004T router's debug interface. Attackers can remotely manipulate the 'cmd' parameter t...

Feb 2, 2026
CVE-2026-1742 4.7

This vulnerability allows remote attackers to upload arbitrary files to the EFM ipTIME A8004T router via the VPN service component. Attackers can expl...

Feb 2, 2026
CVE-2026-1737 5.3

This vulnerability in Open5GS allows remote attackers to trigger a reachable assertion in the CreateBearerRequest handler, potentially causing denial ...

Feb 2, 2026
CVE-2026-1738 5.3

CVE-2026-1738 is a reachable assertion vulnerability in Open5GS SGWC component that allows remote attackers to cause denial of service by manipulating...

Feb 2, 2026
CVE-2026-1739 5.3

A null pointer dereference vulnerability in Free5GC's Policy Control Function (PCF) allows remote attackers to cause denial of service by crashing the...

Feb 2, 2026
CVE-2026-1735 4.3

This CVE describes a command injection vulnerability in Yealink MeetingBar A30's Diagnostic Handler component. Attackers with physical access to the d...

Feb 2, 2026
CVE-2026-1736 5.3

A reachable assertion vulnerability in Open5GS SGWC component allows remote attackers to cause denial of service by sending specially crafted requests...

Feb 2, 2026
CVE-2026-1734 5.3

This vulnerability allows unauthorized remote access to the crontab endpoint in Zhong Bang CRMEB versions up to 5.6.3. Attackers can exploit this miss...

Feb 2, 2026
CVE-2026-1733 4.3

This CVE describes an improper authorization vulnerability in Zhong Bang CRMEB's store integration API endpoint. Attackers can manipulate the order_id...

Feb 1, 2026
CVE-2023-54343 6.4

QWE DL 2.0.1 mobile web application has a persistent cross-site scripting (XSS) vulnerability in path parameters that allows attackers to inject malic...

Feb 1, 2026
CVE-2022-50940 6.4

Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting (XSS) vulnerability in the name parameter. Attackers can inject malicious scr...

Feb 1, 2026
CVE-2022-50941 6.4

BootCommerce 3.2.1 contains persistent cross-site scripting (XSS) vulnerabilities in guest order checkout input fields. Attackers can inject malicious...

Feb 1, 2026
CVE-2022-50942 5.4

CVE-2022-50942 is a client-side cross-site scripting vulnerability in Icinga Web 2.8.2 that allows attackers to inject malicious scripts through the i...

Feb 1, 2026